Risk, Compliance & Information Security Executive
HybridAtaşehir, Istanbul, Turkey
Job Summary
Manage PCI DSS (Service Provider Level 1) and ISO 27001 compliance and certification processes while analyzing security vulnerabilities to propose effective technical and organizational controls. Plan and coordinate internal and external penetration tests, perform regular vulnerability assessments using tools such as Nessus and Qualys, and conduct risk assessments to prepare corrective action plans. Use SIEM and GRC tools for monitoring and reporting, prepare for audits by managing relevant documentation, and raise awareness across the organization on compliance and security best practices. This hybrid role at Ticimax supports secure software products in the e-commerce landscape.
Required Qualifications
- Solid understanding of PCI DSS and ISO 27001 frameworks
- Hands-on experience with vulnerability scanning tools (e.g. Nessus, Qualys) and SIEM platforms
- Familiarity with GRC systems and compliance reporting
- Strong documentation, audit preparation, and analytical skills
- Proficiency in English (written and verbal)
Desired Qualifications
- Experience in secure software development practices
- Familiarity with remediation follow-ups after penetration tests
- Relevant certifications (e.g. OSCP, CEH, ISO 27001 Lead Auditor, CISA)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.